Skip to main content
Mallory
1 malware family

UNC2682

Also known asUNC2682

UNC2682 is a Mandiant-tracked intrusion activity cluster associated with post-exploitation activity on SonicWall Email Security (ES). In the described intrusion, the actor deployed a web shell on a SonicWall ES server, gaining command execution with inherited NT AUTHORITY\SYSTEM privileges, and attempted to reduce visibility by clearing the SonicWall webUI log file. Mandiant states it prevented UNC2682 from completing its mission, and the actor’s ultimate objectives remain unknown. Observed tradecraft included heavy use of living-off-the-land techniques for credential access and post-exploitation. UNC2682 exported the HKLM\SAM, HKLM\SYSTEM, and HKLM\SECURITY registry hives, and used rundll32.exe with comsvcs.dll MiniDump to dump memory from lsass.exe and the Apache Tomcat process. The actor staged data by using an existing 7-Zip installation to compress a subdirectory of \data\archive, which contains daily archives of emails processed by SonicWall ES. After a pause consistent with offline password recovery attempts, UNC2682 moved laterally because the victim reused the same local Administrator password across multiple domain hosts. For lateral movement and remote execution, the actor used Impacket WMIEXEC.py over DCOM/WMI, followed by brief internal reconnaissance before containment and removal. No additional aliases, sub-groups, or nation-state attribution are provided in the content beyond the Mandiant tracking name UNC2682.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

5 of 15 tactics10 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0003
Persistence
1 technique
T1505
Server Software Component
T1505.003
Web Shell
TA0005
Stealth
1 technique
T1070
Indicator Removal
T1070.001
Clear Windows Event Logs
TA0006
Credential Access
1 technique
T1003
OS Credential Dumping
T1003.001
LSASS Memory
T1003.002
Security Account Manager
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.003
Distributed Component Object Model
TA0009
Collection
1 technique
T1560
Archive Collected Data
ARSENAL

Associated malware families

1 malware family attributed to this actor across reporting.

ACTIVITY FEED

Recent activity

1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.

No news coverage yet. Advisories and community discussion only.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping6

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.